Shell access to your ix2/ix4 exposed! “Get yer red hot ssh here!”

So, I promised you guys in Iomega ix4-200d data reconstruction, ssh and more! that I would expose the password to login to the ix2 and ix4 as soon as I could.    Well, your wait is finally over!

Let’s start as you normally would, by logging into the support console!

http://192.168.1.1/support.html

Click on Support Files

Whoa, what’s that I highlighted there and even tossed in an arrow?! Can I MAKE it any more straight forward? Psst.. Click on Support Files :)

Click on the Dump button

Ooh, what’s that little guy down there? Dump? Yea, I didn’t even notice this before (because I had shell access myself ;)) but this is for your benefit!

The system will go through "Gathering system state…"

Open up your dump file!

Why yes, I did go mad with clicking colors and arrows in the win7 version of MSPaint.. Okay, but I digress. :)

Click that bad boy, which will include dump data about your system! Download it, and open it!

Drill down into the dump –> config –> etc –> and open up the file named “shadow”   (dump-20100107225620.tar.gz\dump-20100107225620\config\etc)

Wait, what?! Is that an exposed hash with the root password from your shadow?!

Find your shadow File in there, and lo and behold, you will have your Iomega root users hash!    Now it’s just a matter of cracking it!

It is beyond the scope of this article to tell you how to actually crack the pwd.. (giggle) go here, download john the ripper and you’ll do just fine :)

Password CRACKED in seconds! user:root pwd:soho

Taking my seed from my system and running it through a simple alphanumeric search, I come up with username root, password soho! That was easy! That works if you have NO Password set!

Through a collaborative effort with @randyjcress @Kiwi_Si @VirtualisedReal and @gabvirtualworld we were able to determine that by using soho and whatever password you use on the system, that should do it! And really, the credit does primarily go to @randyjcress for leading us in that specific direction so props randy! :)

ie: admin pwd is apples, so login using sohoapples – This is still undergoing verification, but I thought I’d share it out there, while we sort it out!

Disclaimer: The means to perform all of these tasks has been replicated and verified in the wild without requiring any intimate knowledge of the inner workings of the system. 

Iomega ix4-200d data reconstruction, ssh and more!

So for those of you who know me, you know I initially complained about a data reconstruction problem with my ix4-200d! I accidently pulled the power cable out (doh!) and then my system came up JUST fine, and said “Data reconstruction, 2%” Yea, it said that FOREVER – And it did nothing and got nowhere! Regardless of how many reboots I made! (Though my data access was fine!)

ix4-200d !

And even going to the “Update Device Software” tab, it always reported “The device software is up to date” Which I now know is a LIE! LIES I SAY! :)

I did a little searching and came across an updated firmware! (oh my!) however it didn’t say it’d do anything about data reconstruction problems! But hey, I always like to be running the latest/greatest, so I downloaded and installed the latest firmware! StorCenter ix4-200d Firmware Version 2.1.25.229: Read First (You’ll find this to be quick and painless!)

Well, some minutes passed and all of a sudden the system was all “DATA RECONSTRUCTION IS HAPPENING IN THE HIZZY!” Okay, not in those exact words.. but I don’t feel like pulling my power to try to reproduce the problem – needless to say, my data reconstruction resumed and finished in short order! Score one for the bucko! (dated reference much?!)

So I deep dove into the system to see what else had changed! (nothing consequential that I could find) but my journey to find a way to ssh this box had not ended! I was determined! I must.. I must.. I must increase my SSH ability! And while searching I came across not only this webpage SSH/Shell access to iomega StorCenter ix2 but that little gem of a webpage included this little link at the bottom! http://ip-of-nas/support.html – Which when you browse to it on your ix4, you end up seeing a page which looks like… this!

Support Page to enable SSH on ix4-200d /support.html

This has a few little gems, only two of which will I look at in any detail – Support Access and Recover Disks

Support Access to enable SSH Storage Recovery Verification - Force Disk data reconstruction maybe?

Well, Support Access looks pretty damn straight forward! Check the box, reboot, and SSH will be enabled (permanently!)

The Storage Recovery Verification is a bit more interesting – my “guess” is that it allows you the ability to force the data reconstruction many of us complain of! Again, I have no intention of forcing the deal to try to see what happens if I fail my system – You simply let me know if this works for you – with data reconstruction woes :)

Getting Shell (ssh) access to the ix4-200d!

Sweet, eh! So, I feel comfortable sharing the process on how to do this.. because frankly, I had to find it from the outside looking in! So I definitely grant you good luck on solving your data reconstruction, firmware updating, and enabling SSH on your NAS!   Until I find an externally cited source though.. I cannot share with you my passwd I used to log in to my ix4 ;)

As promised!  Shell access to your ix2/ix4 exposed! “Get yer red hot ssh here!”

If you come across a site referencing it though, I’d be glad to add it to the mix!  Thanks for your patience.. and look forward to a future post around getting my ‘gigabit runs at 100mb’ problem :)